Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107914

Quick assessment

Affected
backdropcms Backdrop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Backdrop CMS 1.34 版本(不含 1.34.5)以及 1.35 版本(不含 1.35.1)中,系统在提供压缩归档文件时,对配置导出的保护不足。然而,该漏洞的影响有限,因为配置导出必须由具有“同步、导入和导出配置”权限的用户预先请求。

CVSS 7.8 · High EPSS 0.12% · P2

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 2

VendorProduct Version RangeStatus
backdropcms Backdrop 1.34.0< 1.34.5 affected
1.35.0< 1.35.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107914

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file_unmanaged_delete operation occurs. Therefore, many archives could persist: config.tar.gz, config_0.tar.gz, config_1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
清理环节不完整
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
backdropcms Backdrop 1.34.0 ~ 1.34.5 -

II. Public POCs for CVE-2026-107914

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107914

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107914 (2)

Vendor Advisories for CVE-2026-107914 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107914

No comments yet


Leave a comment